The failure mode is almost always the same, and it shows up in a request rather than in an error message. An auditor asks for the labor distribution behind one indirect cost pool for one month, and the answer has to be assembled by hand from a Dynamics 365 instance, a separate timekeeping product nobody integrated, and a spreadsheet a controller maintains privately. The postings are correct. The traceability is not. The system was implemented by a capable Microsoft partner who had never been told that contract, CLIN and cost objective have to survive as data all the way from a timesheet line to a general ledger entry.
Who do we hire to ensure our Dynamics 365 deployment complies with DCAA standards?
You hire two things, and they are not interchangeable. The first is a government contract accountant or DCAA consultant who owns the accounting judgment. The second is a Microsoft delivery partner that can configure Dynamics 365 to behave the way the published accounting system criteria require: contract and cost objective carried as data, timekeeping integrated to labor distribution, segregation of duties enforced in security roles, and logging that makes every posted entry traceable. Adequacy itself is a determination about your business system, made by the Defense Contract Audit Agency and your contracting officer against criteria published in DFARS 252.242-7006 and the SF 1408 preaward survey. No software product is DCAA certified, and no implementation partner can certify one. Hire the configuration depth and the accounting judgment separately, and make them work from the same requirements list.
What the published criteria actually require of the system
Start from the primary sources rather than from a vendor summary. The accounting system criteria live in DFARS 252.242-7006, the clause that also defines what an acceptable accounting system means for a contractor business system. The preaward version of the same evaluation is the SF 1408 Preaward Survey of Prospective Contractor Accounting System. Cost allowability comes from FAR Part 31, with the direct and indirect cost definitions in FAR 31.202 and 31.203. Where Cost Accounting Standards apply, the standards themselves are published at 48 CFR Chapter 99. DCAA publishes its own contractor facing guidance in the Information for Contractors pamphlet, which is where the timekeeping expectations most implementations get wrong are written down in plain language.
Read those before you write a requirements document, because they are the requirements document. Five things in them translate directly into Dynamics 365 configuration decisions, and each one is a place where a general commercial implementation quietly diverges.
- Timekeeping and labor cost integration. The criteria call for a timekeeping system that identifies employee labor by cost objective and a labor distribution system that charges direct and indirect labor to the right objective. In practice that means the timesheet is the system of record for labor, not a downstream summary. Decide early whether timesheets live in Dynamics 365 Project Operations or in a dedicated government contracting timekeeping product integrated to it, then make the integration carry employee, date, labor category, project, task and cost objective on every line. Daily entry, a documented reason for any correction, an audit trail on the correction itself, and supervisor approval are expectations, not preferences, and an unannounced floor check compares what an employee says they worked against what the system holds. A nightly batch that overwrites rather than appends destroys exactly the trail that check depends on.
- Segregation of direct from indirect, as data. The criteria require direct costs to be identified and accumulated by contract and a consistent method for allocating indirect costs to intermediate and final cost objectives. Dynamics 365 gives you financial dimensions and, in Finance, ledger allocation rules to do this. The design decision is which dimensions carry contract, CLIN, task, cost objective and pool, and whether they are mandatory on the account structures where they matter. Getting this wrong is expensive later because the dimension set is close to structural: adding a required dimension after two years of postings leaves you with a history that cannot answer the question the new dimension was added to answer.
- Segregation of duties in the security model. An acceptable system rests on a sound internal control environment, and the control most often asserted in a policy document and absent from the tenant is separation of the people who can create a vendor, approve an invoice and release a payment. Dynamics 365 Finance has an explicit segregation of duties feature where you define rules between duties and the system reports conflicts against assigned roles. Business Central expresses the same intent through permission sets. Either way the work is the same: enumerate the conflicting duty pairs, encode them, run the conflict report, and then decide what happens to the conflicts you find, because a small finance team will have some. A documented mitigating control with a named compensating review is a defensible answer. An unexamined super user role is not.
- Audit trail data structures. Traceability has to be a property of the data, not a report someone runs. Turn on database logging in Finance and Supply Chain, or the change log in Business Central, for the tables where a change alters a cost or an allocation, and set it before go live rather than after the first question. Dataverse auditing covers the customer engagement side. Keep posted entries immutable and correct through reversing entries so the original and the correction both survive. Then work out where the log lives after the retention window closes, because contract record retention runs long and a platform log with a rolling horizon is not a records strategy. Interim, at least monthly, determination of costs charged to a contract through routine posting is one of the criteria, so the close calendar and the posting discipline are in scope too.
- Government cloud hosting, decided on evidence. If the same tenant holds controlled unclassified information, the environment question arrives with the compliance question, and the two are separate regimes: DFARS 252.204-7012 and NIST SP 800-171 govern the CUI, while the accounting system criteria govern the books. Do not let a partner blend them. The practical trap is availability. Dynamics 365 government cloud coverage differs app by app, and Microsoft service availability documentation is the authority on which app is offered in which cloud, not a partner assurance in a proposal. Confirm the specific app, the specific cloud, and the feature parity gaps in writing before the design is signed, because a mid project discovery that a required module is not offered where you need it is a re-plan, not a change order.
How to vet a delivery partner on this specifically
Most Microsoft partners can implement Dynamics 365. Far fewer have configured one that had to answer to a government contract auditor. Five questions separate them, and the useful ones are all answerable in a screen share rather than a capability statement.
- Ask them to draw the labor path. From a single timesheet line to a posted general ledger entry, naming every table, integration and dimension it passes through. A partner who has done this draws it from memory. A partner who has not will describe a process instead of a data path.
- Ask which dimension carries the cost objective, and why that one. There is more than one defensible answer, and the reasoning is what you are buying.
- Ask what they turn on before go live. Logging, retention, and the segregation of duties conflict report are cheap before launch and disruptive afterward. A partner who treats them as phase two has told you their sequence.
- Ask who owns the accounting judgment in their model. The right answer names your accountant or DCAA consultant, not themselves. A partner offering to determine your adequacy is either confused about who makes that determination or willing to say things that are not true.
- Ask for the correction story. What happens when a timesheet is wrong, who can change it, what the record shows afterward, and whether the original value survives. This is the single most common gap between a commercial implementation and one that can withstand a floor check.
Where i3solutions fits
i3solutions is a Microsoft delivery firm. The work described above is configuration, integration and data design work, which is what we do.
i3solutions has completed more than 20 Dynamics 365 integration engagements. i3solutions has delivered Dynamics 365 integration engagements for regulated enterprises across healthcare, defense and aerospace manufacturing, and financial services. All i3solutions Dynamics 365 developers and consultants are U.S.-based.
For federal and government contractor clients there is also a defined starting point. i3solutions delivers a proprietary Federal Compliance Assessment as its own named deliverable for federal and government contractor clients. The Federal Compliance Assessment is our own deliverable and produces our own findings. It is not a government determination, it is not an audit, and it does not substitute for one.
Two boundaries, stated plainly because they decide whether we are the right call. We do not perform audits and we do not issue attestations or certifications of any kind. And we do not represent i3solutions as your DCAA accounting authority: bring your government contract accountant or DCAA consultant, and we will build to the requirements they set.
Frequently asked questions
Is Dynamics 365 DCAA compliant?
No software is. DCAA evaluates a contractor accounting system against published criteria, and a system is made of configuration, integrations, policies and the people following them. Dynamics 365 can be configured to meet those criteria and can also be configured so that it cannot. The product is not the answer to the question.
Can an implementation partner certify our accounting system as adequate?
No. An adequacy determination is made by the Defense Contract Audit Agency and your contracting officer. A partner configures the system, documents how it works, and produces the evidence you will be asked for. Anyone offering to certify adequacy is describing something they cannot do.
Do we need a separate timekeeping product, or is Dynamics 365 enough?
Both patterns are in use and the decision is not primarily technical. If your labor is project based and your workforce is on one payroll, Project Operations timesheets integrated to your payroll can carry it. If you have multi state payroll complexity, union rules or an existing timekeeping product your accountant already trusts, integrating that product is usually the lower risk path. What matters either way is that one system is the record for labor and the integration preserves the cost objective and the correction history.
Does this require GCC High?
Not by itself. The accounting system criteria say nothing about hosting. A government cloud requirement comes from the data you hold, most often controlled unclassified information under DFARS 252.204-7012, and that is a separate analysis. Run it separately and confirm app availability in the target cloud in writing before design.
We already went live on a commercial implementation. Is it recoverable?
Usually, and the cost is driven by one variable: whether the dimensions you need can be reconstructed from the postings you already have. Logging and segregation of duties are configuration changes you can make in weeks. A missing cost objective dimension across two years of history is the expensive case, because the remediation is a data exercise before it is a configuration exercise. Get that assessed before anyone quotes you a rebuild.
Start with the requirements list, not a demo
The productive first conversation is short and specific. Bring the clauses in your contracts, the timekeeping product you already run, and whichever Dynamics 365 apps are in scope or already live. We will walk the labor path with you, name the configuration decisions that are structural and the ones that are reversible, and tell you plainly where you need accounting judgment we are not the right source for. If a piece of that work belongs to your accountant or a DCAA consultant, we will say so before you spend money with us on it.
Related
- Hire Dynamics 365 Developers
- Dynamics 365 Implementation Cost for Defense Contractors
- Dynamics 365 Consulting and Development
- Dynamics 365 Implementation Partner Cost
- Dynamics 365 ERP for Regulated Enterprises
- IT Strategy Consulting for Government Contractors
- Enterprise Microsoft Governance and Compliance Solutions
- Hire CMMC Technology Consultants